Re: [Cfrg] Review of draft-arciszewski-xchacha-02

Tony Arcieri <bascule@gmail.com> Tue, 18 December 2018 16:05 UTC

Return-Path: <bascule@gmail.com>
X-Original-To: cfrg@ietfa.amsl.com
Delivered-To: cfrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 762F3130EBA for <cfrg@ietfa.amsl.com>; Tue, 18 Dec 2018 08:05:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.098
X-Spam-Level:
X-Spam-Status: No, score=-0.098 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RIDbS6C9fQrn for <cfrg@ietfa.amsl.com>; Tue, 18 Dec 2018 08:05:18 -0800 (PST)
Received: from mail-oi1-x22e.google.com (mail-oi1-x22e.google.com [IPv6:2607:f8b0:4864:20::22e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1A909130EB5 for <cfrg@ietf.org>; Tue, 18 Dec 2018 08:05:18 -0800 (PST)
Received: by mail-oi1-x22e.google.com with SMTP id a77so2358908oii.5 for <cfrg@ietf.org>; Tue, 18 Dec 2018 08:05:18 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=EA1E2MCxueJ4/kMgljrwwOBkZKqjkvdy9gL4ZFmzeOM=; b=eXZiKGvdfEiMwVnVjWy4yKnha6tkaebEoCsQRxxdViCZ32zMU0R+GQHivrE6+dmfKM LLyQhhO+McUWUyESQ7ymx2GrEWx0ovBBlSihu1M3h6TvQvHY8Zeth3w2SxBUpiHB/vzB 8woQlBbLwQnAV8K+t5zmvGbnQN1KKT4WDHU3K92TcUOmKhZXntwKh11NM6hEzWGAG3m6 n/IcFpJfxL3IlnvPRLRUFVpfzqlkCTYajxuQPr5lCgwiK+Q3T6VMaHW7zNCY/ae1xOu0 s3Bfk9WI9DCTqSkwuQ+XMCZ3nzR2q6GQAOD912xWesiOh/ofC22PwLCvbubhvhpkul9r bF8Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=EA1E2MCxueJ4/kMgljrwwOBkZKqjkvdy9gL4ZFmzeOM=; b=H/dzFI3uA8odWr1QjSvnSU5xh+fjqOEtVM9UVl85C4n4FUCll1KHYegy3ceBKEFVJ6 2L5ehYAyjHdrhf5yglDc6TF3umEQcqf99e4GxCuy7LPXRiQekwWjC4cbXdItOhLqNNV1 AWFEJS0cKLTBTc3BoBDQv3hhVX1uf8T0SBpk2tS4rAWoYVKEQss+ZVY6DETrdo2P59LZ c3IiS9p36Z5v1i0QPNAAZ6WA7DUiRm9YONjuY9Wqqndij5eZAaIOs9Eoxl8J7V0zyvhH TI3Tosr0c6XoC9LHj9Kc0tMlzNnuKl+edQHYFBqxCi4XCe6RU+U7EAz90VsasN3A3GKM GtuQ==
X-Gm-Message-State: AA+aEWaU/nDVw0on3DwTK2MOsSgFIZm6HVbcpT65CFNJdaMpa+OQRUuC PTcajMEchPv5YEG+TObbQV9cTwanm/YTSQfwAEA=
X-Google-Smtp-Source: AFSGD/Uwc/1w/2aFw9QnwYBNVFmWeKeW107apqjd+p0ELDF+9CrvpRlkz5hMzdZPA8X8KREbTiq/2lKBpGF8sIQEURM=
X-Received: by 2002:aca:e142:: with SMTP id y63mr7730633oig.314.1545149117125; Tue, 18 Dec 2018 08:05:17 -0800 (PST)
MIME-Version: 1.0
References: <99CCB4A1-9CC1-4611-95C5-CEEA985024F8@gmail.com> <600285EA-7387-4455-9D7F-9FD42AB26920@akamai.com>
In-Reply-To: <600285EA-7387-4455-9D7F-9FD42AB26920@akamai.com>
From: Tony Arcieri <bascule@gmail.com>
Date: Tue, 18 Dec 2018 08:05:06 -0800
Message-ID: <CAHOTMVJkWK0S_MZ3tog1hcLXLjs27Wk-pMr7puYKnoC8=Q71Tg@mail.gmail.com>
To: "Salz, Rich" <rsalz@akamai.com>
Cc: Neil Madden <neil.e.madden@gmail.com>, "cfrg@ietf.org" <cfrg@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000004059cd057d4e10a9"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cfrg/BFGlhExc4FjpMJKhBxXGDkSuhBU>
Subject: Re: [Cfrg] Review of draft-arciszewski-xchacha-02
X-BeenThere: cfrg@irtf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Crypto Forum Research Group <cfrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/options/cfrg>, <mailto:cfrg-request@irtf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cfrg/>
List-Post: <mailto:cfrg@irtf.org>
List-Help: <mailto:cfrg-request@irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/cfrg>, <mailto:cfrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Dec 2018 16:05:20 -0000

On Tue, Dec 18, 2018 at 5:16 AM Salz, Rich <rsalz@akamai.com> wrote:

> To repeat what I said earlier, "XChaCha" is a bad name.  Can we use
> XNChaCha or something similar to show that is an extended NONCE, and not
> something like extended keysize or number of rounds?


As someone who routinely vocalizes the names of these constructions,
they're already a bit unwieldy. I wish we would've Curve25519 => Curve255
and Ed25519 => Ed255 just to make them easier to pronounce.

I'd rate "XChaCha" as "good" on the pronounceability scale, and XNChaCha...
less so

-- 
Tony Arcieri